What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Contact Form With Shortcode contact-form-with-shortcode allows Reflected XSS.This issue affects Contact Form With Shortcode: from n/a through <= 4.2.5.
Explanation of Vulnerability in Simple Terms
02Summary
Contact Form With Shortcode versions 4.2.5 and earlier contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts into form fields that execute in visitors' browsers when the form is viewed. The vulnerability affects the scope beyond the vulnerable component, potentially compromising user sessions and data. Site administrators should update to a version newer than 4.2.5.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that run in visitors' browsers when they view the contact form.
Potential impact on your site
04Site Impact
Visitor sessions and data can be compromised; attackers can steal credentials or redirect users to malicious sites.
Conditions required to exploit
05Prerequisites
Visitor must view a page containing the vulnerable contact form with injected malicious content.
Key dates
06Disclosure timeline
February 14, 2025
CVE published
May 11, 2026
Record updated